Tero Kivinen, AuthenTec

Slides:



Advertisements
Similar presentations
Submission Title: [Add name of submission]
Advertisements

<month year> <doc.: IEEE doc> May 2015
June 2006 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Proposed Scenarios for Usage Model Document.
Submission Title: Coding example for the ULI
Jan 2014 Tero Kivinen, INSIDE Secure
Jan 2014 Tero Kivinen, INSIDE Secure
Submission Title: [MC EventsList] Date Submitted: [11Jul00]
doc.: IEEE <doc#>
doc.: IEEE <doc#>
doc.: IEEE <doc#>
Project: IEEE Wireless Personal Area Networks (WPANs)
March 2008 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Toumaz response to TG6 Call for Applications]
Submission Title: Example of P2P route discovery
Submission Title: Example of P2P route discovery
Submission Title: Coding example for the ULI
July 2013 Robert Moskowitz, Verizon
Robert Moskowitz, Verizon
Robert Moskowitz, Verizon
<month year> doc.: IEEE <xyz> January 2001
Submission Title: Coding example for the ULI
Robert Moskowitz, Verizon
Robert Moskowitz, Verizon
<month year> <doc.: IEEE doc> December 2015
Jan 2015 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: Jan 2015 closing report Date Submitted: Jan.
Submission Title: [One-to-many and many-to-many peering procedures]
September g Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Recognition of Hiroshi.
<month year> doc.: IEEE <xyz> November 2000
Submission Title: [IEEE WPAN Mesh Reference Model]
July 2018 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Extensions to IEEE in support of.
doc.: IEEE /XXXr0 Sep 19, 2007 June 2009
Submission Title: [Frame and packet structure in ]
November 2006 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Simplified geometry for the usage model.
<month year> <doc.: IEEE doc> May 2015
July 2013 Robert Moskowitz, Verizon
<month year>20 Jan 2006
July 2018 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Extensions to IEEE in support of.
<month year> <Nov 2018>
Nov 2013 Robert Moskowitz, Verizon
Submission Title: [One-to-many and many-to-many peering procedures]
May 2018 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Considerations on general MAC frame] Date Submitted:
April 19 July 2010 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: WNG Closing Report for San Diego.
<month year> <doc.: IEEE doc> January 2016
<month year> <doc.: IEEE doc> March 2015
Mar 2015 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: Mar 2015 closing report Date Submitted: Mar.
March 2019 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [DF6 Radio-burst length over PSDU size] Date.
<month year> <doc.: IEEE doc> March 2015
Jan 2014 Tero Kivinen, INSIDE Secure
May 2013 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: May 2013 closing report Date Submitted: May.
Tero Kivinen, AuthenTec
Tero Kivinen, INSIDE Secure
Submission Title: May Closing report for IG 9a
Submission Title: May Closing report for IG 9a
<month year> <doc.: IEEE doc> July 2015
<month year> doc.: IEEE <030158r0> <March 2003>
Submission Title: [LB 28 Results] Date Submitted: [14 March 2005]
Robert Moskowitz, Verizon
Mar 2008 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Resolution for Comment 70 ] Date Submitted:
Mar 2008 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Resolution for Comment 70 ] Date Submitted:
Nov Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Report on IEEE PAC Draft Status]
<month year> <doc.: IEEE doc> September 2015
August, 2008 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [Improve the latency between GTS request.
<month year> <doc.: IEEE doc> March 2015
Submission Title: TG9ma Closing Report for July Meeting
July 2003 doc.: IEEE <03/242> July 2003
Jul 12, /12/10 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: Dependable Interest Group Closing.
Submission Title: TG9ma Agenda for September Meeting
Jan 2008 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: TeraHertz Closing Report Date Submitted: January.
Submission Title: TG9ma Closing Report for July Meeting
Submission Title: TG9ma Closing Report for September Meeting
12/15/2019 Project: IEEE P Working Group for Wireless Personal Area Networks (WPANs) Submission Title: [AWGN Simulation Results] Date Submitted:
Presentation transcript:

Tero Kivinen, AuthenTec May 2012 Project: IEEE P802.15 Working Group for Wireless Personal Area Networks (WPANs) Submission Title: IKEv2 over TG9 Date Submitted: 17 May, 2012 Source: Tero Kivinen, Company: AuthenTec Address: Eerikinkatu 28, FI-00180 Helsinki, Finland Voice:+358 20 500 7800, FAX: +358 20 500 7801, E-Mail: kivinen@iki.fi Re: KMP documents for TG9 Abstract: IKEv2 KMP over TG9 Purpose: To add IKEv2 as one of the KMPs to the 15.4 and 15.7 Notice: This document has been prepared to assist the IEEE P802.15. It is offered as a basis for discussion and is not binding on the contributing individual(s) or organization(s). The material in this document is subject to change in form and content after further study. The contributor(s) reserve(s) the right to add, amend or withdraw material contained herein. Release: The contributor acknowledges and accepts that this contribution becomes the property of IEEE and may be made publicly available by P802.15. Tero Kivinen, AuthenTec

Tero Kivinen Atlanta, GA May 17, 2012 IKEv2 KMP over TG9 Tero Kivinen Atlanta, GA May 17, 2012 Tero Kivinen, AuthenTec

May 2012 The IKEv2 Protocol Specified in the IETF document RFC5996 for KMP for IPsec Key management between peers Exchange of secure identities 4 packet session key establishment SIGMA compliant Multiple authentication methods Shared secrets Public Keys (either certificates or raw keys) EAP Secure password methods Tero Kivinen, AuthenTec

The IKEv2 Protocol Flow May 2012 Initiator Responder HDR, SAi1, KEi, Ni → ← HDR, SAr1, KEr, Nr HDR, SK{IDi, AUTH, SAi2, TSi, TSr} → ← HDR, SK{IDr, AUTH, SAr2, TSi, TSr} HDR = Header SAi1, SAr1, SAi2, SAr2 = Security Association Payloads KEi, KEr = Key Exchange Payloads Ni, Nr = Nonce Payloads IDi, IDr = Identification Payloads AUTH = Authentication Payloads TSi, TSr = Traffic Selector Payloads Tero Kivinen, AuthenTec

Profile and Additions to IKEv2 May 2012 Profile and Additions to IKEv2 Need to add group key distribution Need to define what kind of Traffic selectors are used any ↔ any? Specify which features are not needed NAT-T Cookie exchange Tero Kivinen, AuthenTec

Use Cases for IKEv2 Use Cases May 2012 Use Cases for IKEv2 Use Cases Most likely in devices which already need strong cryptographic operations (Diffie- Hellman, Public Key operations) and need to have those on hardware anyways Devices which can share KMP for all layers MAC, IP, and where application layer can use IPsec as IP layer protection (for example core) Tero Kivinen, AuthenTec